PaperCut Software is warning users of its NG and MF print management solutions that a zero-day vulnerability is being exploited in the wild.
The flaw has yet to be assigned a CVE identifier and no technical details have been shared. The vendor released emergency patches on Friday and urged customers to install them.
PaperCut also recommends disconnecting the application server from the internet and restricting access to trusted IPs.
“We are aware of confirmed customer incidents and are treating this matter with the highest priority. Our investigation is ongoing,” the company said in its advisory.
It’s unclear who is behind the exploitation of the zero-day vulnerability.
PaperCut has shared some indicators of compromise (IoCs), including suspicious activity associated with pc-app.exe, the main executable for the PaperCut Application Server.
The company also noted that unexpectedly truncated or deleted server.log files could indicate an intrusion. The removal or modification of log files can suggest that attackers are attempting to cover their tracks.
This is not the first PaperCut NG/MF vulnerability exploited in the wild. CISA’s Known Exploited Vulnerabilities (KEV) catalog includes three flaws, and this latest weakness has not been added.
Two of the security holes included in the KEV list have been exploited in ransomware attacks.
Roughly 1,000 PaperCut instances are currently exposed to the internet, a majority in North America and Europe, according to data from the ShadowServer Foundation.
UPDATE: Huntress has published a blog post describing attacks observed against two customer environments. The company noted that the vulnerability “gives an unauthenticated attacker remote control over PaperCut’s trusted configuration, which could be used to execute arbitrary Java code inside the application’s process.”
UPDATE 2: The identifiers CVE-2026-81578 and CVE-2026-82078 have been assigned to the vulnerability.
*updated information on pc-app.exe IoCs
Related: Recent Citrix NetScaler Vulnerability Exploited in the Wild


